Home / Privacy
Privacy policy
How SOMES collects, uses, stores and protects personal data, and the rights you hold over it.
Who we are
The Somalia Evaluation Society (SOMES) is the data controller for personal data processed through somes.so. Contact us at info@somes.so, or write to SOMES, KM4, Mogadishu, Banaadir, Somalia.
What we collect
- Account and membership data: name, email, phone number, organisation, professional profile, region, languages, membership tier and payment status.
- Learning data: courses enrolled, completion records and certificates issued.
- Content you submit: abstracts, papers, forum posts, directory entries, mentorship requests, job postings and contact messages.
- Transaction data: the amount, date, method and reference of payments. We do not store full card numbers or mobile money PINs.
- Technical data: IP address, browser type and pages visited, used to keep the site secure and to understand which resources are useful.
Why we process it
- To administer your membership, learning and certification (contractual necessity)
- To communicate about events, courses and the newsletter (consent, withdrawable at any time)
- To meet audit, financial and legal obligations (legal obligation)
- To keep the site and member data secure, and to prevent fraud (legitimate interests)
We do not sell personal data. We do not use it for advertising. We do not process special category data such as health, religion, political opinion or ethnicity, and we deliberately do not collect clan or tribal affiliation — admission to SOMES rests on professional criteria alone.
Who sees it
Your directory profile is visible to other signed-in members only, and you control which fields appear. Staff and board members see personal data only where their role requires it. Payment processors and the hosting provider act on our instructions under contract. External auditors may examine financial records as part of the annual audit. We do not otherwise disclose personal data unless required by law.
How long we keep it
Membership records are kept for the duration of membership and for seven years afterwards, matching the financial records retention period in the financial manual. Newsletter subscriptions are kept until you unsubscribe. Contact messages are kept for two years. Anonymous whistleblowing reports are retained only as long as needed for the investigation and its record.
Your rights
- Access a copy of the data we hold about you
- Correct data that is inaccurate or incomplete
- Erase your data where there is no overriding legal or contractual reason to retain it
- Restrict or object to processing, including direct marketing
- Receive your data in a portable, machine-readable format
- Withdraw consent at any time, without affecting processing already carried out
- Complain to a supervisory authority
To exercise any of these, email info@somes.so or use the data controls in your member portal. We respond within 30 days.
Security
Data is transmitted over encrypted connections and stored with access restricted by role. Two-factor authentication is available on all accounts and required for administrative and financial roles. Administrative actions on member and financial records are written to an audit log. Suspected breaches are assessed immediately and notified to affected individuals where there is a risk to their rights.
Cookies
We use a small number of cookies and equivalent local storage: strictly necessary ones for sign-in and security, and preference ones that remember your language and contrast settings. Analytics cookies are set only if you consent, and you can change that choice at any time from the consent banner. Declining analytics does not restrict any part of the site.
Children
The site is not directed at children under 16. Student membership is open to those aged 16 and above; applicants under 18 require a guardian's consent.
Changes
Material changes to this policy are announced on the site and, for members, by email. The date of the current version is shown in the member portal.